Cybersecurity programs
Security you can actually show someone.
Buying security products is easy and proves nothing. A program is the difference between hoping you are covered and being able to demonstrate it to an insurer, a client, a board or a regulator when they ask.
The form this is really about
Your insurance renewal has eleven questions on it this year.
Last year it had three. Now it wants to know whether every account uses multi-factor authentication, how often you test restores, whether staff get security training, and what your incident response plan says. Somebody has to tick those boxes, and ticking them wrongly is worse than not having the cover.
The same questions arrive from clients running vendor reviews, and from the bank, and eventually from whoever is buying your business. They are all asking the same thing: can you show us, rather than tell us.
The distinction that matters
Tools are not a program.
What most businesses have
- Antivirus on the computers, probably
- Multi-factor on some accounts, added in a hurry
- Backups running, never tested
- Training done once, two years ago
- No idea which of these is the weak one
What a program adds
- A written picture of where you actually stand
- A plan with an order, so the biggest risk goes first
- Evidence, kept current, for whoever asks
- A rehearsed answer for the day something happens
- Someone accountable for all of it
The products matter. They are just the easiest part, and the part every provider sells. What is usually missing is the structure around them.
Included, not extra
Most of this already comes with your agreement.
Security is not something we sell alongside fully managed and co-managed IT. It is part of both, running from the first month, and this is what that baseline covers.
Who can get in
- Multi-factor authentication on every account that matters
- A password manager for your staff, so they stop reusing one
- Administrator accounts kept separate from everyday ones
- Access reviewed, and leavers shut down the same day
- Sign-ins from places your people are not, flagged
The machines
- System updates and patching on a schedule, across every device
- Protection on computers, servers and phones
- Hard drives encrypted, so a lost laptop is not a lost database
- Equipment past the end of support flagged before it is a problem
- An inventory, so nothing is quietly unmanaged
Email and data
- Filtering tuned to the scams aimed at your industry
- Records set so nobody can convincingly impersonate your domain
- Links and attachments checked before anyone opens them
- Rules about where company information is allowed to go
- Backup of your Microsoft 365 data, which Microsoft does not do
Your people
- Short security training, repeated rather than done once
- Phishing simulations, used to teach rather than to catch out
- New starters set up correctly from their first morning
- Somebody to ask when an email looks wrong, before clicking
- Guidance written for staff, not for technicians
Watching it
- Monitoring and alerting, so we usually know before you do
- Logs kept, so questions can be answered after the fact
- Regular scanning for known weaknesses
- Backups tested, not just reported as successful
- A plain-language summary at your review
The network
- A business firewall, configured rather than plugged in
- Guest and staff networks kept properly apart
- Remote access that does not open a door to everyone
- Wi-Fi secured, including the part nobody has looked at since 2019
- Changes documented as they happen
Where the baseline comes from
We work from CIS and NIST rather than inventing a standard.
Two bodies of work do the heavy lifting. The CIS Controls are a prioritised list of safeguards, ordered by what actually prevents the most damage, and grouped so a small business can start at the first group and grow into the second. The NIST Cybersecurity Framework gives the structure a program hangs on: identify, protect, detect, respond, recover.
That matters to you for two practical reasons. It means the order we do things in is not our opinion, and it means when an insurer, a client or an auditor asks what you are working to, there is a real answer with a name on it rather than a description of our habits.
You will not be asked to read either document. That is our job.
- CIS Controls, first group as the floor
- The second group as you grow
- NIST for the program structure
- A named standard, not our preferences
So what is a program then
The baseline protects you. The program proves it.
Comes with managed and co-managed
- Everything in the six groups above
- Kept current as things change
- Reviewed at your regular catch-up
- No separate line on the invoice
What a program adds on top
- A formal review of where you stand, in writing
- A costed roadmap with the risks in order
- An evidence file kept ready for whoever asks
- Senior ownership, through a vCISO
- Tabletop exercises and penetration testing
Most businesses need the baseline and nothing more for a long time. The program becomes worth it when somebody external starts asking you to demonstrate it, or when what you hold makes the answer matter more than usual.
How the program runs
Six parts, in this order.
You do not need all six on day one. You do need to know which one you are missing.
Find out where you stand
A review of what you have, what it covers and what it does not. Holistic rather than a tool inventory, because the gaps usually sit between the products rather than inside them. You get a written picture in language you can hand to your board.
Get a plan with an order to it
Every review produces a list. The useful part is the sequencing: what genuinely reduces risk first, what can wait a quarter, and what is being sold to you as urgent but is not. Costed, so it can go in a budget rather than an ambition.
Fix the technical layer
Multi-factor everywhere it belongs, email filtering tuned to the scams aimed at your industry, device protection, and access reviewed so leavers actually lose access. Implemented in a way your staff will tolerate, because a control people route around is not a control.
Train the people
Close to nine in ten breaches trace back to human error, which makes your staff the largest part of your defence whether you have equipped them or not. Short, specific, repeated and measured. More on that below.
Rehearse the bad day
A plan nobody has practised falls apart at the worst possible moment. A tabletop exercise puts your key people through a realistic scenario before it is real, and reliably finds the gap nobody knew was there.
Keep the evidence current
The file that answers the insurer, the client questionnaire and the board paper. Maintained as things change rather than assembled in a panic, so the next request takes an afternoon instead of a fortnight.
vCISO
A security lead, without hiring a security lead.
Somewhere between fifty staff and a serious compliance obligation, businesses hit a point where security needs somebody senior owning it. Hiring that person is expensive and, for most businesses this size, more capacity than the job actually needs.
A virtual chief information security officer is that role, shared. They set the strategy, own the roadmap, sit in the meetings where risk gets decided, and translate between what your technical people say and what your board needs to hear. Balanced against what the business can actually carry, rather than a maximalist list that gets ignored.
- Strategy and roadmap ownership
- Board and client reporting
- Regulatory and insurer questions
- Works with your IT team, not over them
The human layer
Training that people actually finish.
Annual compliance training that everyone clicks through in silence changes nothing. These are the parts that do.
Ongoing
Short modules, on your topics
Videos of a few minutes rather than an afternoon, built around the threats your industry actually faces. Progress is tracked, so you know who has done it rather than assuming.
Topics follow recognised guidance rather than whatever is in the news, and the set is tailored to your organisation.
Measured
Phishing simulations
Realistic test emails sent to your staff, with the result used to teach rather than to embarrass. Somewhere between eighty-five and ninety percent of organisations face ongoing phishing attempts, so this is rehearsal for something already happening.
The click rate is the number worth watching. It should fall, and if it does not, the training needs changing rather than repeating.
Live
Sessions where people can ask
Recorded modules cannot answer the question your bookkeeper actually has about the invoice that looked wrong last Tuesday. Live sessions can, and that question is usually the most valuable part of the hour.
Tailored to your user base rather than delivered from a script.
When you are further along
For businesses past the basics.
These are worth doing once the foundations hold. Done too early they produce a long report confirming what you already knew.
Tabletop exercises
Your key people and executives are walked through a realistic breach scenario and asked to respond as they would instinctively. No systems are touched. What gets tested is the plan, and the decision-making.
It reliably finds the gaps: the contact list that is out of date, the decision nobody is sure who makes, the assumption that somebody else was handling notifications. Actions get reviewed, the plan gets rewritten, and it is repeated as people change.
Penetration testing
Controlled, ethical attacks against your systems and applications, from outside and inside, following the NIST standard. It goes past automated scanning to find the root cause of what is genuinely exploitable, with a written account of how each one was used.
Worth doing once your vulnerability scans have stopped returning long lists of critical findings. Before that point, the scan is cheaper and tells you the same thing.
Obligations
The rules that apply to you here.
PIPEDA
Federal private sector privacy law, covering personal information collected in the course of commercial activity. It carries a mandatory breach reporting obligation, which is the part most businesses discover too late.
PIPA, British Columbia
The provincial equivalent for most BC private sector organisations, including a lot of businesses that assume the federal act is the only one that applies to them.
Contractual and sector rules
Often stricter than the legislation. Client contracts, professional body requirements, insurer conditions and GDPR where you hold information about people in Europe. These are usually what forces the deadline.
We are not a law firm and we will not tell you that you are compliant. What we do is build the technical and evidence side so that when your lawyer or your insurer asks, the answers exist.
When somebody asks for proof
Audits and compliance have their own page.
The two sit close together and they are not the same job. Security is the work of being protected. Audit is the work of demonstrating it to an insurer, a client, a funder, a regulator or a board, in the form they have asked for.
Both are included with fully managed and co-managed IT, and audit work is also available on its own if somebody else looks after your systems.
- Insurer and client questionnaires
- Funder and grant requirements
- Board and governance reporting
- Audits & compliance →
Questions we get asked
The things owners actually want to know.
Pulled from the central library, tagged for this page. All questions and answers →
Related
Often taken alongside this.
Start with where you actually stand.
Half an hour, no charge. Bring the questionnaire that prompted this, if there was one. Worst case you leave knowing which single thing to fix first.
Would rather write?
Send this and we will reply, usually the same business day. No call unless you want one.
Protected by reCAPTCHA.